First published: Thu Apr 25 2013(Updated: )
Buffer overflow in the SNMP implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices 4.x and 5.x before 5.2(5) allows remote authenticated users to execute arbitrary code via a crafted SNMP request, aka Bug ID CSCtx54822.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =4.0 | |
Cisco NX-OS | =4.0\(0\)n1\(1a\) | |
Cisco NX-OS | =4.0\(0\)n1\(2\) | |
Cisco NX-OS | =4.0\(0\)n1\(2a\) | |
Cisco NX-OS | =4.0\(1a\)n1\(1\) | |
Cisco NX-OS | =4.0\(1a\)n1\(1a\) | |
Cisco NX-OS | =4.0\(1a\)n2\(1\) | |
Cisco NX-OS | =4.0\(1a\)n2\(1a\) | |
Cisco NX-OS | =4.0\(4\)sv1\(1\) | |
Cisco NX-OS | =4.0\(4\)sv1\(2\) | |
Cisco NX-OS | =4.0\(4\)sv1\(3\) | |
Cisco NX-OS | =4.0\(4\)sv1\(3a\) | |
Cisco NX-OS | =4.0\(4\)sv1\(3b\) | |
Cisco NX-OS | =4.0\(4\)sv1\(3c\) | |
Cisco NX-OS | =4.0\(4\)sv1\(3d\) | |
Cisco NX-OS | =4.1\(3\)n1\(1\) | |
Cisco NX-OS | =4.1\(3\)n1\(1a\) | |
Cisco NX-OS | =4.1\(3\)n2\(1\) | |
Cisco NX-OS | =4.1\(3\)n2\(1a\) | |
Cisco NX-OS | =4.1.\(2\) | |
Cisco NX-OS | =4.1.\(3\) | |
Cisco NX-OS | =4.1.\(4\) | |
Cisco NX-OS | =4.1.\(5\) | |
Cisco NX-OS | =4.2 | |
Cisco NX-OS | =4.2\(1\) | |
Cisco NX-OS | =4.2\(1\)n1\(1\) | |
Cisco NX-OS | =4.2\(1\)n2\(1\) | |
Cisco NX-OS | =4.2\(1\)n2\(1a\) | |
Cisco NX-OS | =4.2\(1\)sv1\(4\) | |
Cisco NX-OS | =4.2\(1\)sv1\(4a\) | |
Cisco NX-OS | =4.2\(1\)sv1\(5.1\) | |
Cisco NX-OS | =4.2\(2\) | |
Cisco NX-OS | =4.2\(3\) | |
Cisco NX-OS | =4.2\(4\) | |
Cisco NX-OS | =4.2\(6\) | |
Cisco NX-OS | =4.2\(8\) | |
Cisco NX-OS | =4.2.\(2a\) | |
Cisco NX-OS | =5.0 | |
Cisco NX-OS | =5.0\(2\) | |
Cisco NX-OS | =5.0\(2\)n1\(1\) | |
Cisco NX-OS | =5.0\(2\)n2\(1\) | |
Cisco NX-OS | =5.0\(2\)n2\(1a\) | |
Cisco NX-OS | =5.0\(2a\) | |
Cisco NX-OS | =5.0\(3\) | |
Cisco NX-OS | =5.0\(3\)n1\(1\) | |
Cisco NX-OS | =5.0\(3\)n1\(1a\) | |
Cisco NX-OS | =5.0\(3\)n1\(1b\) | |
Cisco NX-OS | =5.0\(3\)n1\(1c\) | |
Cisco NX-OS | =5.0\(3\)n2\(1\) | |
Cisco NX-OS | =5.0\(3\)n2\(2\) | |
Cisco NX-OS | =5.0\(3\)n2\(2a\) | |
Cisco NX-OS | =5.0\(3\)n2\(2b\) | |
Cisco NX-OS | =5.0\(5\) | |
Cisco NX-OS | =5.1 | |
Cisco NX-OS | =5.1\(1\) | |
Cisco NX-OS | =5.1\(1a\) | |
Cisco NX-OS | =5.1\(2\) | |
Cisco NX-OS | =5.1\(3\) | |
Cisco NX-OS | =5.1\(3\)n1\(1\) | |
Cisco NX-OS | =5.1\(3\)n1\(1a\) | |
Cisco NX-OS | =5.1\(4\) | |
Cisco NX-OS | =5.1\(5\) | |
Cisco NX-OS | =5.1\(6\) | |
Cisco NX-OS | =5.2 | |
Cisco NX-OS | =5.2\(1\) | |
Cisco NX-OS | =5.2\(3\) | |
Cisco NX-OS | =5.2\(3a\) | |
Cisco NX-OS | =5.2\(4\) | |
Cisco NX-OS | =6.0\(1\) | |
Cisco NX-OS | =6.0\(2\) | |
Cisco NX-OS | =6.1 | |
Cisco NEXUS 7000 Series Switch | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 9-Slot Firmware | ||
Cisco MDS 9000 Series Multilayer Switches |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1180 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2013-1180, upgrade your Cisco NX-OS to version 5.2(5) or later, or 6.1(1) or later.
CVE-2013-1180 affects Cisco NX-OS on Nexus 7000 devices running software versions prior to 5.2(5) and 6.1(1), as well as MDS 9000 devices.
CVE-2013-1180 can be exploited via crafted SNMP requests by remote authenticated users.
As of now, there have been no widespread reports confirming active exploitation of CVE-2013-1180.